Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn ordinary business interactions into a conduit for credential theft and data loss. The group, estimated to have accumulated $6.7 billion in loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. In recent weeks, the group has siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has been used to hijack decentralized finance (DeFi) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims unlikely to realize their security has been breached until the damage has been done.